Solution: Some information regarding the vulnerability was disclosed on a public mailing list, before Sendmail.org had released an updated version. Sendmail.org has therefore rushed to issue an updated version, but the various OS vendors have not released any updated packages yet.
It has not been reported that this vulnerability is being exploited on the Internet, but since some information of the vulnerability has been available since yesterday, the sendmail service should be closed until an updated version has been installed!
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.